Home / Alt manpages / proc_diskstats(5)

  • proc_diskstats(5)
  • File format
  • linux

Read Linux Disk I/O Counters from /proc/diskstats

You will read the kernel's cumulative disk counters, identify the device you care about, and calculate a change between two snapshots. The workflow uses ordinary, read-only shell commands and does not need sudo. Allow about ten minutes if you already know the device name.

This guide describes the interface on the Linux 6.8.0-139-generic kernel used here. The installed proc_diskstats(5) page comes from Linux man-pages 6.7-2 and points to the kernel I/O statistics documentation for the field definitions. The file is generated by the running kernel, so the devices and numbers on your machine will differ.

1. Confirm that the interface is present

/proc/diskstats is a virtual, read-only file. It is normally present when the proc filesystem is mounted. Check it without changing anything:

$ test -r /proc/diskstats && echo "readable"
readable
$ head -n 3 /proc/diskstats
  7       0 loop0 2975 0 272108 26583 0 0 0 0 0 26546 26583 0 0 0 0 0 0
  7       1 loop1 3287 0 16314 1666 0 0 0 0 0 1591 1666 0 0 0 0 0 0
  7       2 loop2 5553 0 26408 4240 0 0 0 0 0 3793 4240 0 0 0 0 0 0

Each line begins with a major number, a minor number and a device name. The remaining values are the device's statistics. The example includes loop devices, which are real block devices but are often not the physical disk you want to measure.

2. Find the device name

Use lsblk to see the block-device names and their relationships. This is also read-only:

$ lsblk -o NAME,TYPE,SIZE,MOUNTPOINTS
NAME        TYPE  SIZE MOUNTPOINTS
nvme0n1     disk  477G
|-nvme0n1p1 part  512M /boot/efi
`-nvme0n1p2 part 476G /
loop0       loop   64M

Your layout may use names such as sda, vda or mmcblk0. Choose a disk or partition deliberately. A disk line and its partition lines are separate records, and adding them together without understanding the distinction can count related I/O twice.

Checkpoint: select an exact name and confirm that it appears in the file:

$ DEVICE=nvme0n1
$ awk -v wanted="$DEVICE" '$3 == wanted { print }' /proc/diskstats
259       0 nvme0n1 255999 814 12369153 47919 996852 81 36123024 425995 0 301795 580470 0 0 0 0 60602 106555

If that command prints nothing, the name is wrong or the device disappeared. Re-run lsblk; do not guess a line by position because device ordering can change.

3. Read the 17 statistics

For a whole disk, fields 1 to 11 cover completed reads and writes, sectors, timing and I/O currently in progress. Fields 12 to 15 cover discards. Fields 16 and 17 cover flush requests and their time. The first three columns of the file are not part of this numbering.

Useful fields after the device name
FieldMeaningUnit or behaviour
1Reads completedCumulative count
3Sectors readCumulative count
4Time spent readingMilliseconds
5Writes completedCumulative count
7Sectors writtenCumulative count
8Time spent writingMilliseconds
9I/O currently in progressUsually returns to zero
10Time doing I/OMilliseconds
11Weighted time doing I/OMilliseconds weighted by in-flight I/O

The sector counters are counts, not bytes. Keep them as sectors when comparing snapshots unless you have separately established the device's sector size. The timing counters are totals, not current latency. A value such as field 4 is the accumulated time for all reads since the counters were initialised.

Field 9 is different: it is a current count of in-flight I/O and is the field expected to fall back to zero. The other counters are cumulative and generally monotonic, but they can reset after boot, device reattachment, reinitialisation or counter overflow.

4. Take two snapshots and calculate change

To measure activity, record the same line twice with a known delay, then subtract the earlier values from the later ones. This example reports read operations, sectors read, write operations, sectors written and elapsed I/O time:

$ DEVICE=nvme0n1
$ awk -v wanted="$DEVICE" '$3 == wanted { print; exit }' /proc/diskstats > /tmp/diskstats-before
$ sleep 10
$ awk -v wanted="$DEVICE" '$3 == wanted { print; exit }' /proc/diskstats > /tmp/diskstats-after
$ awk 'NR == FNR { before[1]=$4; before[3]=$6; before[5]=$8; before[7]=$10; before[10]=$13; next }
       { printf "reads +%.0f, sectors read +%.0f, writes +%.0f, sectors written +%.0f, I/O time +%.0f ms\n", $4-before[1], $6-before[3], $8-before[5], $10-before[7], $13-before[10] }' /tmp/diskstats-before /tmp/diskstats-after
reads +42, sectors read +8192, writes +17, sectors written +4096, I/O time +31 ms

The temporary files contain only the two selected lines and can be removed after checking the result:

$ rm -f /tmp/diskstats-before /tmp/diskstats-after

This removal is safe because the files are measurement snapshots, not system configuration. If you need to keep the evidence, copy it to a controlled location instead. The example's ten-second interval is arbitrary; use a longer interval for a quieter workload and a shorter one for an interactive check.

Do not interpret the sample numbers as a rate until you divide each delta by the interval. In the example, 42 reads in ten seconds is 4.2 reads per second. A counter that decreases usually indicates a reset or a bad comparison, so discard that interval and take fresh snapshots.

5. Avoid the partition and device traps

Partition records do not carry exactly the same meaning as whole-disk records. On modern kernels, partition lines expose four partition statistics: reads issued, sectors read, writes issued and sectors written. The kernel documentation also explains that partition accounting happens at a different point in request processing. Compare like with like: use the same device name for both snapshots and do not silently substitute nvme0n1p2 for nvme0n1.

For a small, known set of devices, the corresponding sysfs file can be easier to target:

$ cat /sys/block/nvme0n1/stat
255999 814 12369153 47919 996852 81 36123024 425995 0 301795 580470 0 0 0 0 60602 106555

The sysfs line contains the same 17 statistics without the major number, minor number or device name. For many devices, /proc/diskstats avoids opening a separate file for each device. Neither interface is a substitute for a higher-level monitoring tool when you need graphs, alerting or persistent history.

Done means

  • /proc/diskstats is readable and the chosen device name was verified against its output.
  • You can distinguish the three identifying columns from the 17 statistic fields.
  • You read sectors and timings as cumulative counters, not instantaneous values.
  • You compared the same device across two timestamps and checked for resets.
  • You kept disk and partition records separate and avoided counting related lines twice.